References https://github.com/winterwolf32/CVE-S---Penetration_Testing_POC-/blob/master/%E6%B3%9B%E5%BE%AE%20e-cology%20OA%20%E5%89%8D%E5%8F%B0SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://www.aliyun.com/product/news/15034 https://cloud.tencent.com/developer/article/2443506 https://github.com/adysec/POC/blob/main/wpoc/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEe-cology%E6%8E%A5%E5%8F%A3HrmService%E5%89%8D%E5%8F%B0SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://www.cnblogs.com/ffx1/p/12653555.html https://bbs.chaitin.cn/topic/629 https://baizesec.github.io/bylibrary/%E6%BC%8F%E6%B4%9E%E5%BA%93/01-CMS%E6%BC%8F%E6%B4%9E/%E6%B3%9B%E5%BE%AE/%E6%B3%9B%E5%BE%AE%20e-cology%20OA%20%E5%89%8D%E5%8F%B0SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E/ https://cloud.tencent.com/developer/article/2566926 https://zhi.oscs1024.com/category/%E6%BC%8F%E6%B4%9E/page/8 https://github.com/Threekiii/Vulnerability-Wiki/blob/master/docs-base/docs/oa/%E6%B3%9B%E5%BE%AEOA-e-cology-FileDownloadForOutDoc%E5%89%8D%E5%8F%B0SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://www.cnblogs.com/pursue-security/p/17677247.html https://blog.csdn.net/weixin_43981050/article/details/131679936 https://jx-yanxin.com/h-nd-11.html https://wxb.fzu.edu.cn/info/1015/1885.htm
Related Vulnerabilities泛微ecology8 getCptInfoMap 存在SQL注入漏洞PoC泛微E-cology10 /papi/passport/appnew/login/appLogin 未授权访问漏洞泛微-Ecology10 getFieldValueFun SQL注入漏洞泛微 e-cology10 /papi/em/transform/downLoadSyslog 文件读取漏洞PoCecology-execforstr-rce: Weaver Ecology ExecForStr Remote Command ExecutionPoCweaver-ecology9-doc-list-sqli: Weaver E-cology9 api/doc/out/more/list SQL InjectionPoCweaver-getemdslist-disclosure: Weaver E-cology getEmDsList Sensitive Information Disclosure泛微E-ecology 10 /papi/file/module/upload SQL 注入漏洞泛微 E-Cology /hrm/hrm_e9/orgChart/js/jquery/plugins/jqueryFileTree/connectors/jqueryFileTree.jsp 目录遍历漏洞泛微ecology10 存在sql注入漏洞泛微E-Cology9 /services/WorkPlanService SQL 注入漏洞PoC泛微E-cology 10 /papi/em/transform/getEmDsList 信息泄露漏洞泛微E-cology10 dubboApi 存在远程代码执行漏洞